CVE-2026-55609
### Impact An arbitrary file write vulnerability (CWE-73, External Control of File Name or Path) exists in the `consciousness-explorer` component of `sublinear-time-solver`. The MCP `export_state` (and `import_state`) tool accepted a user-supplied `filepath` argument and passed it directly to `fs.writeFileSync` / `fs.readFileSync` without constraining the destination or rejecting path traversal. An attacker able to invoke the MCP tool could write or overwrite any file accessible to the server process (e.g. `~/.ssh/authorized_keys`, application files), leading to integrity loss and potential service disruption. The same sink class was present in the main solver MCP server (`saveVectorToFile` / `loadVectorFromFile`). ### Affected versions - `consciousness-explorer` < 1.1.2 - `sublinear-time-solver` < 1.6.0 - `sublinear` (crates.io) < 0.2.0 ### Patches - `[email protected]` - `[email protected]` - `[email protected]` State/vector files are now confined to a dedicated directory (overridable via `$CONSCIOUSNESS_EXPLORER_STATE_DIR` / `$SUBLINEAR_SOLVER_VECTOR_DIR`), a basename-only contract is enforced (rejecting separators, `..`, NUL/control chars, hidden files, and Windows reserved names), and files are opened with `O_NOFOLLOW | O_CLOEXEC` mode `0o600`. Covered by 14 regression tests in `tests/consciousness/safe-path.test.mjs`. **Breaking change:** callers must now pass a basename, not an absolute path. ### Workarounds Do not expose the MCP server to untrusted clients; restrict `export_state` to trusted local users; run the server under a low-privilege account with a restricted working directory.
Properties
- ghsa_id
- GHSA-xc9g-j69q-37xw
- severity
- high
- summary
- consciousness-explorer / sublinear-time-solver MCP export_state has an arbitrary file write
- cvss_score
- 7.1
- cve_id
- CVE-2026-55609
- cvss_vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
- is_ghsa_only
- false
- ghsa_published
- 2026-08-25T18:35:32Z
- source_url
- https://github.com/advisories/GHSA-xc9g-j69q-37xw
- ghsa_updated
- 2026-08-25T18:35:33Z
Related Entities (6)
VULNERABLE_TO (2)
AFFECTS (2)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph